EP4619922A1 - Systems and methods for enhancing digital wallet security - Google Patents

Systems and methods for enhancing digital wallet security

Info

Publication number
EP4619922A1
EP4619922A1 EP23822198.0A EP23822198A EP4619922A1 EP 4619922 A1 EP4619922 A1 EP 4619922A1 EP 23822198 A EP23822198 A EP 23822198A EP 4619922 A1 EP4619922 A1 EP 4619922A1
Authority
EP
European Patent Office
Prior art keywords
computer program
user
verification
product
service provider
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
EP23822198.0A
Other languages
German (de)
French (fr)
Inventor
Jai CHAWLA
Dipti AHUJA
Reetu Bok
Gerardo GEAN
Maurice SHORROSH
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
JPMorgan Chase Bank NA
Original Assignee
JPMorgan Chase Bank NA
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by JPMorgan Chase Bank NA filed Critical JPMorgan Chase Bank NA
Publication of EP4619922A1 publication Critical patent/EP4619922A1/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/42Confirmation, e.g. check or permission by the legal debtor of payment
    • G06Q20/425Confirmation, e.g. check or permission by the legal debtor of payment using two different networks, one for transaction and one for security confirmation
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/36Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes
    • G06Q20/367Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes involving electronic purses or money safes
    • G06Q20/3674Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes involving electronic purses or money safes involving authentication
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/322Aspects of commerce using mobile devices [M-devices]
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/32Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
    • G06Q20/326Payment applications installed on the mobile devices
    • G06Q20/3265Payment applications installed on the mobile devices characterised by personalisation for use
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/36Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes
    • G06Q20/363Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes with the personal data of a user
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification

Definitions

  • Embodiments generally relate to systems and methods for enhancing digital wallet security.
  • a method for enhancing digital wallet security may include: (1) receiving, at a service provider computer program executed by a service provider electronic device, a request from a computer program executed by a user electronic device for user authentication with a product identifier for a product; (2) generating, by the service provider computer program, a verification code; (3) communicating, by the service provider computer program, the product identifier and the verification code to a verification computer program executed by a backend associated with a provider of the product identifier, wherein the verification computer program is configured to retrieve user contact information for a user associated with the product identifier and communicate the verification code to the user electronic device; (4) receiving, by the service provider computer program, a received verification code from the computer program, wherein the received verification code was received at the user electronic device; and (5) communicating, by the service provider computer program, authorization for an action involving the product to the computer program in response to the received verification code matching the verification code.
  • the method may also include communicating, by the service provider computer program, denial for the action involving the product to the computer program in response to the received verification code not matching the verification code.
  • the product may include a banking product
  • the action may include adding the banking product to a digital wallet application executed by the user electionic device.
  • the method may also include communicating, by the verification computer program and to the service provider computer program, denial for the action involving the product to the computer program in response to the received authenticating information not matching the stored authenticating information.
  • the product may be a banking product
  • the action may include adding the banking product to a digital wallet application executed by a user electronic device.
  • the request for authenticating information may be communicated by short messaging service, electronic mail, or in-app messaging.
  • a system may include: a user electronic device executing a user computer program; a service provider electronic device executing a service provider computer program; and a backend executing a verification computer program.
  • the user computer program submits a request to add a product associated with a product identifier to the user computer program to the service provider computer program.
  • the service provider computer program submits a request to authenticate a user associated with the product identifier to the verification computer program.
  • the verification computer program retrieves user contact information associated with the product identifier, communicates a request for authenticating information to the user electronic device using the user contact information; receives received authenticating information from the user electronic device; retrieves stored authenticating information for the user associated with the product identifier; and communicates authorization for an action involving the product to the service provider in response to the received authenticating information matching the stored authenticating infonnation.
  • the verification computer program may communicate no authorization for the action involving the product to the computer program to the service provider in response to the received authenticating information matching the stored authenticating information.
  • the product may be a banking product
  • the action may include adding the banking product to a digital wallet application executed by a user electronic device.
  • the authenticating information may include a personal identification number or a card verification value for the banking product, a driver’s license number for the user, out of wallet information for the user, etc.
  • the user electronic device may also execute a computer program associated with the backend, and the verification computer program communicates the request for authenticating information to the computer program associated with the backend, and the computer program associated with the backend communicates the received authenticating information to the verification computer program.
  • Figure 1 depicts a system for enhancing digital wallet security according to an embodiment.
  • Figure 2 depicts a method for enhancing digital wallet security according to one embodiment.
  • Figure 3 depicts a method for enhancing digital wallet security according to another embodiment.
  • Figure 4 depicts a method for enhancing digital wallet security according to another embodiment.
  • Figure 5 depicts an exemplary computing system for implementing aspects of the present disclosure.
  • Embodiments are directed to systems and methods for enhancing digital wallet security.
  • Embodiments may leverage a financial institution’s knowledge of a customer in order to validate or verify a customer.
  • the third-party digital wallet may request that a service provider (e.g., a payment network operator) generate a verification code, such as a one-time passcode, and provide the verification code to a financial institution that is associated with the banking product.
  • a service provider e.g., a payment network operator
  • a verification code such as a one-time passcode
  • the user may then enter the verification code into the user interface for the digital wallet, and the digital wallet may provide the verification code to the service provider for verification. If the verification code is validated, the banking product may be added to the digital wallet. If the verification code is not validated, the banking product is not added to the digital wallet.
  • the financial institution backend may perform the validation directly using, for example, a verification code, confirmation of an issued card feature confirmation (e.g., last four digits, expiration date, a card verification value (CVV), a personal identification number (PIN), etc.), identification information (e.g., a driver’s license number or a portion thereof, driver’s license expiration date, etc.), out of wallet information verification, or in-application verification using the financial institution’s application (e.g., biometric entry, code entry, etc.).
  • the financial institution may provide “verification as a service” using the contact information that it maintains for its customers.
  • Embodiments may thereby reduce friction in the digital wallet user journey while enhancing the overall security of the digital wallet.
  • Digital wallet application 112 may communicate with service provider computer program 145 that may be executed by service provider electronic device 140.
  • Service provider may be, for example, a payment network operator, such as VISA, MASTERCARD, AMERICAN EXPRESS, or any private label (e.g., closed loop) payment networks.
  • Digital wallet application 112 may communicate with service provider computer program 145 using any suitable network, including, for example, the payment network associated with the service provider.
  • Service provider computer program 145 may also communicate with verification computer program 125 using any suitable network, including, for example, the payment network associated with the service provider.
  • the issuing financial institution may maintain customer information database 130 that may maintain contact information for its customers, including phone numbers, SMS addresses, email address, issuer app identifiers, etc.
  • customer information database 130 may maintain, directly or indirectly, a mapping of bank products to customer profiles.
  • a user may access a digital wallet application that is executed on a user electronic device and, in a user interface for the digital wallet application, may request to add a banking product, such as a credit card, a debit card, a demand deposit account (DDA), a line of credit, a rewards account, etc. to the digital wallet.
  • a banking product such as a credit card, a debit card, a demand deposit account (DDA), a line of credit, a rewards account, etc.
  • the user may enter a banking product identifier, such as a credit card number, may enter an account number, may capture an image of the banking product and the digital wallet application may identify the banking product identifier from the image, etc.
  • the digital wallet application may use the wireless capabilities of the electronic device (e.g., near field communication) to receive the banking product identifier.
  • the user may optionally select a communication channel to receive a verification code on, such as text/SMS, email, voice, in-application messaging, etc.
  • the digital wallet application may request user authentication from a service provider.
  • the digital wallet application may provide the banking product identifier to the service provider and the communication channel identified by the user, if provided.
  • a service provider computer program may generate a verification code, such as a random alphanumeric code.
  • the verification code may have any suitable number of digit and/or characters.
  • the service provider computer program may identify a financial institution that is associated with the banking product, such as an issuer, from the banking product identifier.
  • the service provider computer program may identify the financial institution from, for example, a bank identification number, a routing number, or a user identification of the financial institution.
  • a financial institution computer program executed by the financial institution may retrieve user contact information for the banking product identifier from, for example, a user profile in a customer information database.
  • the user contact information may include a SMS address, an email address, an identifier for a financial institution mobile application, etc.
  • the financial institution computer program may send the verification code to the user electronic device. In one embodiment, if provided, the financial institution computer program may use the communication channel identified by the user.
  • the financial institution computer program may randomly select the communication channel, may select the communication channel that was most recently updated, may select the communication channel that has successfully been used before, etc.
  • the user electronic device may receive the verification code, and the user may enter the verification code into the digital wallet application user interface.
  • the operating system for the user electronic device may pre-populate the user interface with the verification code.
  • the service provider may validate the verification code. If the verification code is valid (e.g., matches the verification code generated by the service provider), in step 245, it may authorize the digital wallet application to add the banking product. If the verification code is not valid (e.g., does not match the verification code generated by the service provider or is not received within a certain period of time), in step 250, it may instruct the digital wallet application to not add the banking product.
  • a user may access a digital wallet application that is executed on a user electronic device and, in a user interface for the digital wallet application, may request to add a banking product, such as a credit card, a debit card, a demand deposit account (DDA), a line of credit, a rewards account, etc. to the digital wallet.
  • a banking product such as a credit card, a debit card, a demand deposit account (DDA), a line of credit, a rewards account, etc.
  • the user may enter a banking product identifier, such as a credit card number, may enter an account number, may capture an image of the banking product and the digital wallet application may identify the banking product identifier from the image, etc.
  • the digital wallet application may use the wireless capabilities of the electronic device (e.g., near field communication) to receive the banking product identifier.
  • the user may optionally select a communication channel to receive a verification code on, such as text/SMS, email, voice, in-application messaging, etc.
  • the digital wallet application may request user authentication from a service provider.
  • the digital wallet application may provide the banking product identifier to the service provider and the communication channel identified by the user, if provided.
  • a service provider computer program may identify a financial institution that is associated with the banking product, such as an issuer, from the banking product identifier.
  • the service provider computer program may identify the financial institution from, for example, a bank identification number, a routing number, or a user identification of the financial institution.
  • the service provider computer program may then submit a request for authentication and the banking product identifier to the financial institution. If provided, the service provider computer program may also communicate the communication channel for the verification code that was identified by the user.
  • a financial institution computer program executed by the financial institution such as a verification computer program, may retrieve user contact information for the banking product identifier from, for example, a user profile in a customer information database.
  • the user contact information may include a SMS address, and email address, an identifier for a financial institution mobile application, etc.
  • the financial institution computer program may retrieve authenticating information for the banking product identifier from, for example, a user profile in a customer information database.
  • Authenticating information may include, for example, infonnation for the bank product, such as a CVV or PIN for the bank product, or information for the user, such as the user’s driver’s license number or expiration date, the user’s social security number, the user’s home ZIP code, etc.
  • authenticating infonnation may include a challenge that may be based, for example, on the user’s cunent location, a challenge phrase and a response, out-of-wallet information out of wallet answers (e.g., first car, favorite food, high school mascot, etc.), etc. Any suitable authenticating information may be used as is necessary and/or desired.
  • the financial institution computer program may use biometric authentication conducted by the financial institution application and the electronic device operating system.
  • the financial institution computer program may send a communication to the user electronic device requesting an input.
  • the financial institution computer program may request that the user provide information related to the information retrieved from the user profile, such as the PIN, the CVV, information for the user, etc.
  • the financial institution computer program may request biometric authentication from the user using the financial institution application.
  • the communication channel may be the communication channel identified by the user.
  • the in-app communication channel may be selected.
  • the communication channel may be selected based on the sensitivity of the information requested. For example, if a CVV, PIN, or personal identifiable information (e.g., some or all of a driver’s license number or a social security number) are to be requested, in-app messaging or other secure communication may be used.
  • CVV chemical vapor deposition
  • PIN physical identifier
  • personal identifiable information e.g., some or all of a driver’s license number or a social security number
  • the financial institution computer program may validate the user input. If the user input is valid (e.g., it matches the information requested), in step 345, the financial institution computer program may authorize the digital wallet application directly or indirectly (e.g., through the service provider computer program and/or the financial institution app) to add the bank product. If the user input is not valid (e.g., does not match the or is not received within a certain period of time), in step 350, the financial institution computer program may instruct the digital wallet application, directly or indirectly, to not add the banking product.
  • the financial institution computer program may instruct the digital wallet application, directly or indirectly, to not add the banking product.
  • the user may have more than one opportunity to enter the correct information.
  • Figure 4 depicts method for enhancing digital wallet security according to another embodiment.
  • a user may access a digital wallet application that is executed on a user electronic device and, in a user interface for the digital wallet application, may request to add a banking product, such as a credit card, a debit card, a demand deposit account (DDA), a line of credit, a rewards account, etc. to the digital wallet.
  • a banking product such as a credit card, a debit card, a demand deposit account (DDA), a line of credit, a rewards account, etc.
  • the user may enter a banking product identifier, such as a credit card number, may enter an account number, may capture an image of the banking product and the digital wallet application may identify the banking product identifier from the image, etc.
  • the digital wallet application may use the wireless capabilities of the electronic device (e.g., near field communication) to receive the banking product identifier.
  • the user may optionally select a communication channel to receive a verification code on, such as text/SMS, email, voice, in-application messaging, etc.
  • the digital wallet application may request user authentication from a service provider.
  • the digital wallet application may provide the banking product identifier to the service provider and the communication channel identified by the user, if provided.
  • the service provider computer program may identify a financial institution that is associated with the banking product, such as an issuer, from the banking product identifier.
  • the service provider computer program may identify the financial institution from, for example, a bank identification number, a routing number, or a user identification of the financial institution.
  • the service provider computer program may then submit a request for authentication and the banking product identifier to the financial institution. If provided, the service provider computer program may also communicate the communication channel for the verification code that was identified by the user.
  • a financial institution computer program executed by the financial institution may generate a verification code, such as a random alphanumeric code.
  • the verification code may have any suitable number of digits and/or characters.
  • the service provider computer program may generate and provide the verification code to the financial institution computer program, and the financial institution computer program may use that verification code to authenticate the user.
  • the financial institution computer program may retrieve user contact information for the banking product identifier from, for example, a user profile in a customer information database.
  • the user contact information may include a SMS address, and email address, an identifier for a financial institution mobile application, etc.
  • the financial institution computer program may send the verification code to the user electronic device.
  • the financial institution computer program may use the communication channel identified by the user.
  • the financial institution computer program may randomly select the communication channel, may select the communication channel that was most recently updated, may select the communication channel that has successfully been used before, etc.
  • the user electronic device may receive the verification code, and the user may enter the verification code into the digital wallet application user interface.
  • the operating system for the user electronic device may pre-populate the user interface with the verification code.
  • the user may enter the verification code to an application associated with the financial institution, such as an issuer application.
  • step 440 the digital wallet application may communicate the entered verification code to the service provider, and the service provider may then provide the entered verification code to the financial institution.
  • the application may provide the verification code to the financial institution without involving the service provider.
  • the financial institution computer program may validate the verification code. If the verification code is valid (e.g., matches the verification code generated by the financial institution computer program), in step 450, the financial institution computer program may authorize the digital wallet application to add the banking product. In one embodiment, this may be done by infoiming the service provider that the authentication was successful, and the service provider may then authorize the digital wallet to add the banking product. In another embodiment, the financial institution computer program may inform the application that is associated with the financial institution, and the application may inform the digital wallet application of the successful authentication by app-to-app communication.
  • the financial institution computer program may instruct the digital wallet application to not add the banking product. This may also be achieved by informing the service provider or the application associated with the financial institution that authentication was unsuccessful.
  • Figure 5 depicts an exemplary computing system for implementing aspects of the present disclosure.
  • Figure 5 depicts exemplary computing device 500.
  • Computing device 500 may represent the system components described herein.
  • Computing device 500 may include processor 505 that may be coupled to memory 510.
  • Memory 510 may include volatile memoiy.
  • Processor 505 may execute computer-executable program code stored in memory 510, such as software programs 515.
  • Software programs 515 may include one or more of the logical steps disclosed herein as a programmatic instruction, which may be executed by processor 505.
  • Memory 510 may also include data repository 520, which may be nonvolatile memoiy for data persistence.
  • Processor 505 and memory 510 may be coupled by bus 530.
  • Bus 530 may also be coupled to one or more network interface connectors 540, such as wired network interface 542 or wireless network interface 544.
  • Computing device 500 may also have user interface components, such as a screen for displaying graphical user interfaces and receiving input from the user, a mouse, a keyboard and/or other input/output components (not shown).
  • Embodiments of the system or portions of the system may be in the form of a “processing machine,” such as a general-purpose computer, for example.
  • processing machine is to be understood to include at least one processor that uses at least one memory.
  • the at least one memory stores a set of instructions.
  • the instructions may be either permanently or temporarily stored in the memory or memories of the processing machine.
  • the processor executes the instructions that are stored in the memory or memories in order to process data.
  • the set of instructions may include various instructions that perform a particular task or tasks, such as those tasks described above. Such a set of instructions for performing a particular- task may be characterized as a program, software program, or simply software.
  • the processing machine may be a specialized processor.
  • the processing machine may be a cloud-based processing machine, a physical processing machine, or combinations thereof.
  • the processing machine executes the instructions that are stored in the memory or memories to process data. This processing of data may be in response to commands by a user or users of the processing machine, in response to previous processing, in response to a request by another processing machine and/or any other input, for example.
  • the processing machine used to implement embodiments may be a general-purpose computer.
  • the processing machine described above may also utilize any of a wide variety of other technologies including a special purpose computer, a computer system including, for example, a microcomputer, mini-computer or mainframe, a programmed microprocessor, a micro- confroller, a peripheral integrated circuit element, a CSIC (Customer Specific Integrated Circuit) or ASIC (Application Specific Integrated Circuit) or other integrated circuit, a logic circuit, a digital signal processor, a programmable logic device such as a FPGA (Field- Programmable Gate Array), PLD (Programmable Logic Device), PLA (Programmable Logic Array), or PAL (Programmable Array Logic), or any other device or arrangement of devices that is capable of implementing the steps of the processes disclosed herein.
  • a programmable logic device such as a FPGA (Field- Programmable Gate Array), PLD (Programmable Logic Device), PLA (Programmable Logic Array), or PAL (Programmable Array Logic), or any other device or arrangement of devices that is
  • the processing machine used to implement embodiments may utilize a suitable operating system.
  • each of the processors and/or the memories of the processing machine may be located in geographically distinct locations and connected so as to communicate in any suitable manner.
  • each of the processor and/or the memory may be composed of different physical pieces of equipment. Accordingly, it is not necessary that the processor be one single piece of equipment in one location and that the memory be another single piece of equipment in another location. That is, it is contemplated that the processor may be two pieces of equipment in two different physical locations. The two distinct pieces of equipment may be connected in any suitable manner. Additionally, the memory may include two or more portions of memory in two or more physical locations.
  • processing is performed by various components and various memories.
  • processing performed by two distinct components as described above in accordance with a further embodiment, may be performed by a single component.
  • processing perfonned by one distinct component as described above may be performed by two distinct components.
  • the memory storage performed by two distinct memory portions as described above may be perfonned by a single memory portion.
  • the memory storage performed by one distinct memoiy portion as described above may be performed by two memory portions.
  • various technologies may be used to provide communication between the various processors and/or memories, as well as to allow the processors and/or the memories to communicate with any other entity; i.e., so as to obtain further instructions or to access and use remote memory stores, for example.
  • Such technologies used to provide such communication might include a network, the Internet, Intranet, Extranet, a LAN, an Ethernet, wireless communication via cell tower or satellite, or any client server system that provides communication, for example.
  • Such communications technologies may use any suitable protocol such as TCP/IP, UDP, or OSI, for example.
  • the instructions or set of instructions used in the implementation and operation of embodiments may be in a suitable form such that the processing machine may read the instructions.
  • the instructions that form a program may be in the form of a suitable programming language, which is converted to machine language or object code to allow the processor or processors to read the instructions. That is, written lines of programming code or source code, in a particular programming language, are converted to machine language using a compiler, assembler or interpreter.
  • the machine language is binary coded machine instructions that are specific to a particular type of processing machine, i.e., to a particular type of computer, for example. The computer understands the machine language.
  • Any suitable programming language may be used in accordance with the various embodiments.
  • the instructions and/or data used in the practice of embodiments may utilize any compression or encryption technique or algorithm, as may be desired.
  • An encryption module might be used to encrypt data.
  • files or other data may be decrypted using a suitable decryption module, for example.
  • the embodiments may illustratively be embodied in the form of a processing machine, including a computer or computer system, for example, that includes at least one memory.
  • the set of instructions i.e., the software for example, that enables the computer operating system to perform the operations described above may be contained on any of a wide variety of media or medium, as desired.
  • the data that is processed by the set of instructions might also be contained on any of a wide variety of media or medium. That is, the particular medium, i.e., the memory in the processing machine, utilized to hold the set of instructions and/or the data used in embodiments may take on any of a variety of physical forms or transmissions, for example.
  • the medium may be in the fonn of a compact disc, a DVD, an integrated circuit, a hard disk, a floppy disk, an optical disc, a magnetic tape, a RAM, a ROM, a PROM, an EPROM, a wire, a cable, a fiber, a communications channel, a satellite transmission, a memory card, a SIM card, or other remote transmission, as well as any other medium or source of data that may be read by the processors.
  • the memory or memories used in the processing machine that implements embodiments may be in any of a wide variety of forms to allow the memory to hold instructions, data, or other infoimation, as is desired.
  • the memory might be in the form of a database to hold data.
  • the database might use any desired arrangement of files such as a flat file arrangement or a relational database arrangement, for example.
  • a user interface includes any hardware, software, or combination of hardware and software used by the processing machine that allows a user to interact with the processing machine.
  • a user interface may be in the form of a dialogue screen for example.
  • a user interface may also include any of a mouse, touch screen, keyboard, keypad, voice reader, voice recognizer, dialogue screen, menu box, list, checkbox, toggle switch, a pushbutton or any other device that allows a user to receive infonnation regarding the operation of the processing machine as it processes a set of instructions and/or provides the processing machine with information.
  • the user interface is any device that provides communication between a user and a processing machine.
  • the information provided by the user to the processing machine through the user interface may be in the form of a command, a selection of data, or some other input, for example.
  • a user interface is utilized by the processing machine that perfonns a set of instructions such that the processing machine processes data for a user.
  • the user interface is typically used by the processing machine for interacting with a user either to convey information or receive information from the user.
  • the user interface might interact, i.e., convey and receive information, with another processing machine, rather than a human user. Accordingly, the other processing machine might be characterized as a user.
  • a user interface utilized in the system and method may interact partially with another processing machine or processing machines, while also interacting partially with a human user.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Accounting & Taxation (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Finance (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computer Security & Cryptography (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

Systems and methods for enhancing digital wallet security are disclosed. In one embodiment, a method may include a service provider computer program: (1) receiving a request from a computer program executed by a user electronic device for user authentication with a product identifier for a product; (2) generating a verification code; (3) communicating the product identifier and the verification code to a verification computer program, wherein the verification computer program is configured to retrieve user contact information for a user associated with the product identifier and communicate the verification code to the user electronic device; (4) receiving, by the service provider computer program, a received verification code from the computer program, wherein the received verification code was received at the user electronic device; and (5) communicating authorization for an action involving the product to the computer program in response to the received verification code matching the verification code.

Description

SYSTEMS AND METHODS FOR ENHANCING DIGITAL WALLET SECURITY
BACKGROUND OF THE INVENTION
1. Field Of The Invention
[0001] Embodiments generally relate to systems and methods for enhancing digital wallet security.
2. Description of the Related Art
[0002] It is not uncommon for an individual to not update contact information with merchants or wallet application providers. Because of this, when a user wishes to add a banking product, such as a credit card, to a digital wallet, or store it for card on file transactions, the merchant or wallet provider may not be able to send a verification message to the user. This leads to users giving up or having to update their contact information before again trying to add the banking product to the digital wallet.
SUMMARY OF THE INVENTION
[0003] Systems and methods for enhancing digital wallet security are disclosed. In one embodiment, a method for enhancing digital wallet security may include: (1) receiving, at a service provider computer program executed by a service provider electronic device, a request from a computer program executed by a user electronic device for user authentication with a product identifier for a product; (2) generating, by the service provider computer program, a verification code; (3) communicating, by the service provider computer program, the product identifier and the verification code to a verification computer program executed by a backend associated with a provider of the product identifier, wherein the verification computer program is configured to retrieve user contact information for a user associated with the product identifier and communicate the verification code to the user electronic device; (4) receiving, by the service provider computer program, a received verification code from the computer program, wherein the received verification code was received at the user electronic device; and (5) communicating, by the service provider computer program, authorization for an action involving the product to the computer program in response to the received verification code matching the verification code.
[0004] In one embodiment, the method may also include communicating, by the service provider computer program, denial for the action involving the product to the computer program in response to the received verification code not matching the verification code.
[0005] In one embodiment, the product may include a banking product, and the action may include adding the banking product to a digital wallet application executed by the user electionic device.
[0006] In one embodiment, the method may also include receiving, by the service provider computer program, an identification of a communication channel to send the verification code to the user electronic device; and communicating, by the service provider computer program, the identification of the communication channel to the verification computer program, wherein the verification computer program is configured communicate the verification code to the user electronic device over the communication channel.
[0007] In one embodiment, the verification code may be communicated to the user electronic device by short messaging service, electronic mail, or in-app messaging. [0008] According to another embodiment, a method for enhancing digital wallet security may include: (1) receiving, by a verification computer program executed by a backend associated with a provider of a product and from a service provider computer program, a request to authenticate a user comprising a product identifier for the product; (2) retrieving, by the verification computer program, user contact infoimation associated with the product identifier; (3) communicating, by the verification computer program, a request for authenticating information to the user contact information; (4) receiving, by the verification computer program, received authenticating information; (5) retrieving, by the verification computer program, stored authenticating information for the user associated with the product identifier; and (6) communicating, by the verification computer program and to the service provider computer program, authorization for an action involving the product in response to the received authenticating information matching the stored authenticating information.
[0009] In one embodiment, the method may also include communicating, by the verification computer program and to the service provider computer program, denial for the action involving the product to the computer program in response to the received authenticating information not matching the stored authenticating information.
[0010] In one embodiment, the product may be a banking product, and the action may include adding the banking product to a digital wallet application executed by a user electronic device.
[0011] In one embodiment, the authenticating information may include a personal identification number or a card verification value for the banking product, a driver’s license number for the user, out of wallet information for the user, etc. [0012] In one embodiment, the method may also include receiving, by the verification computer program and from the service provider computer program, an identification of a communication channel to send the request for authenticating information; and communicating, by the verification computer program, the request for authenticating information over the communication channel.
[0013] In one embodiment, the request for authenticating information may be communicated by short messaging service, electronic mail, or in-app messaging.
[0014] According to another embodiment, a system may include: a user electronic device executing a user computer program; a service provider electronic device executing a service provider computer program; and a backend executing a verification computer program. The user computer program submits a request to add a product associated with a product identifier to the user computer program to the service provider computer program. The service provider computer program submits a request to authenticate a user associated with the product identifier to the verification computer program. The verification computer program retrieves user contact information associated with the product identifier, communicates a request for authenticating information to the user electronic device using the user contact information; receives received authenticating information from the user electronic device; retrieves stored authenticating information for the user associated with the product identifier; and communicates authorization for an action involving the product to the service provider in response to the received authenticating information matching the stored authenticating infonnation.
[0015] In one embodiment, the verification computer program may communicate no authorization for the action involving the product to the computer program to the service provider in response to the received authenticating information matching the stored authenticating information.
[0016] In one embodiment, the product may be a banking product, and the action may include adding the banking product to a digital wallet application executed by a user electronic device.
[0017] In one embodiment, the authenticating information may include a personal identification number or a card verification value for the banking product, a driver’s license number for the user, out of wallet information for the user, etc.
[0018] In one embodiment, the user electronic device may also execute a computer program associated with the backend, and the verification computer program communicates the request for authenticating information to the computer program associated with the backend, and the computer program associated with the backend communicates the received authenticating information to the verification computer program.
BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to facilitate a fuller understanding of the present invention, reference is now made to the attached drawings. The drawings should not be construed as limiting the present invention but are intended only to illustrate different aspects and embodiments.
[0020] Figure 1 depicts a system for enhancing digital wallet security according to an embodiment.
[0021] Figure 2 depicts a method for enhancing digital wallet security according to one embodiment. [0022] Figure 3 depicts a method for enhancing digital wallet security according to another embodiment.
[0023] Figure 4 depicts a method for enhancing digital wallet security according to another embodiment.
[0024] Figure 5 depicts an exemplary computing system for implementing aspects of the present disclosure.
DETAILED DESCRIPTION OF PREFERRED EMBODIMENTS
[0025] Embodiments are directed to systems and methods for enhancing digital wallet security.
[0026] Embodiments may leverage a financial institution’s knowledge of a customer in order to validate or verify a customer.
[0027] In embodiments, when a customer seeks to add a banking product, such as a credit card, to a third-party digital wallet, the third-party digital wallet may request that a service provider (e.g., a payment network operator) generate a verification code, such as a one-time passcode, and provide the verification code to a financial institution that is associated with the banking product.
Because the financial institution may be required to maintain contacts for its customers, the financial institution may send the verification code to contact information for the user from a customer profile that the financial institution maintains for the user. The user may optionally be presented with an option to select a communication channel (e.g., text/SMS), voice (e.g. interactive voice response system), email, in-application, etc.) over which the verification may be sent. Alternatively, the channel may be selected by default (e.g., always text), may rotate among registered channels for the user (e.g., email - text - phone - in-app, etc.), may be selected randomly, etc. [0028] The financial institution may then retrieve contact information for the selected channel, and may send the verification code to the user over the selected communication channel. The user may then enter the verification code into the user interface for the digital wallet, and the digital wallet may provide the verification code to the service provider for verification. If the verification code is validated, the banking product may be added to the digital wallet. If the verification code is not validated, the banking product is not added to the digital wallet.
[0029] In embodiments, the financial institution backend may perform the validation directly using, for example, a verification code, confirmation of an issued card feature confirmation (e.g., last four digits, expiration date, a card verification value (CVV), a personal identification number (PIN), etc.), identification information (e.g., a driver’s license number or a portion thereof, driver’s license expiration date, etc.), out of wallet information verification, or in-application verification using the financial institution’s application (e.g., biometric entry, code entry, etc.). Thus, the financial institution may provide “verification as a service” using the contact information that it maintains for its customers.
[0030] Thus, users need not keep their contact information current with the merchants or third-party wallet providers.
[0031] Embodiments may thereby reduce friction in the digital wallet user journey while enhancing the overall security of the digital wallet.
[0032] Referring to Figure 1, a system for enhancing digital wallet security is disclosed according to an embodiment. System 100 may include user electronic device 110, which may be any suitable electronic device, such as a computer (e.g., workstation, desktop, notebook, laptop, tablet, etc.), smart devices (e.g., smartphones, smartwatches, etc.) Internet of Things (IoT) appliances, etc. User electronic device 110 may execute one or more computer programs or applications, including, for example, digital wallet application 112 and issuer application 114.
[0033] In one embodiment, electronic wallet application may be provided by a third-party wallet provider, a merchant, etc. In one embodiment, the user of user electronic device 110 may add a banking product, such as a credit card, a debit card, etc., to digital wallet application 112.
[0034] Digital wallet application 112 may communicate with service provider computer program 145 that may be executed by service provider electronic device 140. Service provider may be, for example, a payment network operator, such as VISA, MASTERCARD, AMERICAN EXPRESS, or any private label (e.g., closed loop) payment networks.
[0035] Digital wallet application 112 may communicate with service provider computer program 145 using any suitable network, including, for example, the payment network associated with the service provider. Service provider computer program 145 may also communicate with verification computer program 125 using any suitable network, including, for example, the payment network associated with the service provider.
[0036] Issuer application 114 may communicate with verification computer program 125, which may be executed by issuing financial institution electronic device 120. The issuing financial institution may be the financial institution that issued the banking product being added to digital wallet application 112. It should be noted that more than one issuing financial institution may be provided, with each executing its own verification computer program. [0037] Verification computer program 125 may communicate with user electronic device 110, including issuer app 114, a messaging app (not shown), a phone app (not shown), an email app (not shown) etc., using any suitable communication channel or networks, including cellular network, the Internet, etc. For example, verification computer program 125 may communicate with electronic device 110 and/or including issuer app 114 by email, text (e.g., SMS) messaging, voice, in-app communication, etc.
[0038] The issuing financial institution may maintain customer information database 130 that may maintain contact information for its customers, including phone numbers, SMS addresses, email address, issuer app identifiers, etc. In one embodiment, customer information database 130 may maintain, directly or indirectly, a mapping of bank products to customer profiles.
[0039] Referring to Figure 2, a method for enhancing digital wallet security is disclosed according to an embodiment.
[0040] In step 205, a user may access a digital wallet application that is executed on a user electronic device and, in a user interface for the digital wallet application, may request to add a banking product, such as a credit card, a debit card, a demand deposit account (DDA), a line of credit, a rewards account, etc. to the digital wallet. In one embodiment, the user may enter a banking product identifier, such as a credit card number, may enter an account number, may capture an image of the banking product and the digital wallet application may identify the banking product identifier from the image, etc. In one embodiment, the digital wallet application may use the wireless capabilities of the electronic device (e.g., near field communication) to receive the banking product identifier. [0041] In one embodiment, the user may optionally select a communication channel to receive a verification code on, such as text/SMS, email, voice, in-application messaging, etc.
[0042] In step 210, the digital wallet application, or a backend therefore, may request user authentication from a service provider. The digital wallet application may provide the banking product identifier to the service provider and the communication channel identified by the user, if provided.
[0043] In step 215, a service provider computer program may generate a verification code, such as a random alphanumeric code. The verification code may have any suitable number of digit and/or characters.
[0044] In one embodiment, the service provider computer program may identify a financial institution that is associated with the banking product, such as an issuer, from the banking product identifier. For example, the service provider computer program may identify the financial institution from, for example, a bank identification number, a routing number, or a user identification of the financial institution.
[0045] The service provider computer program may then communicate the verification code and the banking product identifier to the financial institution. If provided, the service provider computer program may also communicate the communication channel for the verification code that was identified by the user.
[0046] In step 220, a financial institution computer program executed by the financial institution, such as a verification computer program, may retrieve user contact information for the banking product identifier from, for example, a user profile in a customer information database. The user contact information may include a SMS address, an email address, an identifier for a financial institution mobile application, etc. [0047] In step 225, the financial institution computer program may send the verification code to the user electronic device. In one embodiment, if provided, the financial institution computer program may use the communication channel identified by the user.
[0048] Alternatively, the financial institution computer program may randomly select the communication channel, may select the communication channel that was most recently updated, may select the communication channel that has successfully been used before, etc.
[0049] In step 230, the user electronic device may receive the verification code, and the user may enter the verification code into the digital wallet application user interface. In one embodiment, the operating system for the user electronic device may pre-populate the user interface with the verification code.
[0050] In step 235, the digital wallet application or a backend therefore may communicate the entered verification code to the service provider.
[0051] In step 240, the service provider may validate the verification code. If the verification code is valid (e.g., matches the verification code generated by the service provider), in step 245, it may authorize the digital wallet application to add the banking product. If the verification code is not valid (e.g., does not match the verification code generated by the service provider or is not received within a certain period of time), in step 250, it may instruct the digital wallet application to not add the banking product.
[0052] Referring to Figure 3, a method for enhancing digital wallet security is disclosed according to an embodiment.
[0053] In step 305, a user may access a digital wallet application that is executed on a user electronic device and, in a user interface for the digital wallet application, may request to add a banking product, such as a credit card, a debit card, a demand deposit account (DDA), a line of credit, a rewards account, etc. to the digital wallet. In one embodiment, the user may enter a banking product identifier, such as a credit card number, may enter an account number, may capture an image of the banking product and the digital wallet application may identify the banking product identifier from the image, etc. In one embodiment, the digital wallet application may use the wireless capabilities of the electronic device (e.g., near field communication) to receive the banking product identifier.
[0054] In one embodiment, the user may optionally select a communication channel to receive a verification code on, such as text/SMS, email, voice, in-application messaging, etc.
[0055] In step 310, the digital wallet application, or a back end therefore, may request user authentication from a service provider. The digital wallet application may provide the banking product identifier to the service provider and the communication channel identified by the user, if provided.
[0056] In step 315, a service provider computer program may identify a financial institution that is associated with the banking product, such as an issuer, from the banking product identifier. For example, the service provider computer program may identify the financial institution from, for example, a bank identification number, a routing number, or a user identification of the financial institution.
[0057] The service provider computer program may then submit a request for authentication and the banking product identifier to the financial institution. If provided, the service provider computer program may also communicate the communication channel for the verification code that was identified by the user. [0058] In step 320, a financial institution computer program executed by the financial institution, such as a verification computer program, may retrieve user contact information for the banking product identifier from, for example, a user profile in a customer information database. The user contact information may include a SMS address, and email address, an identifier for a financial institution mobile application, etc.
[0059] In step 325, the financial institution computer program may retrieve authenticating information for the banking product identifier from, for example, a user profile in a customer information database.
[0060] Authenticating information may include, for example, infonnation for the bank product, such as a CVV or PIN for the bank product, or information for the user, such as the user’s driver’s license number or expiration date, the user’s social security number, the user’s home ZIP code, etc. In another embodiment, authenticating infonnation may include a challenge that may be based, for example, on the user’s cunent location, a challenge phrase and a response, out-of-wallet information out of wallet answers (e.g., first car, favorite food, high school mascot, etc.), etc. Any suitable authenticating information may be used as is necessary and/or desired.
[0061] In another embodiment, the financial institution computer program may use biometric authentication conducted by the financial institution application and the electronic device operating system.
[0062] In step 330, the financial institution computer program may send a communication to the user electronic device requesting an input. For example, the financial institution computer program may request that the user provide information related to the information retrieved from the user profile, such as the PIN, the CVV, information for the user, etc. [0063] As another example, the financial institution computer program may request biometric authentication from the user using the financial institution application.
[0064] In one embodiment, the communication channel may be the communication channel identified by the user. For some embodiments, such as biometric authentication, the in-app communication channel may be selected.
[0065] Alternatively, the financial institution computer program may randomly select the communication channel, may select the communication channel that was most recently updated, may select the communication channel that has successfully been used before, etc.
[0066] In one embodiment, the communication channel may be selected based on the sensitivity of the information requested. For example, if a CVV, PIN, or personal identifiable information (e.g., some or all of a driver’s license number or a social security number) are to be requested, in-app messaging or other secure communication may be used.
[0067] In step 335, the user may respond to the financial institution with requested information. In one embodiment, the user may respond using the same communication channel over which the request was received, such as text/SMS, email, voice, in-app, etc.
[0068] In step 340, the financial institution computer program may validate the user input. If the user input is valid (e.g., it matches the information requested), in step 345, the financial institution computer program may authorize the digital wallet application directly or indirectly (e.g., through the service provider computer program and/or the financial institution app) to add the bank product. If the user input is not valid (e.g., does not match the or is not received within a certain period of time), in step 350, the financial institution computer program may instruct the digital wallet application, directly or indirectly, to not add the banking product.
[0069] In one embodiment, the user may have more than one opportunity to enter the correct information.
[0070] Figure 4 depicts method for enhancing digital wallet security according to another embodiment.
[0071] In step 405, a user may access a digital wallet application that is executed on a user electronic device and, in a user interface for the digital wallet application, may request to add a banking product, such as a credit card, a debit card, a demand deposit account (DDA), a line of credit, a rewards account, etc. to the digital wallet. In one embodiment, the user may enter a banking product identifier, such as a credit card number, may enter an account number, may capture an image of the banking product and the digital wallet application may identify the banking product identifier from the image, etc. In one embodiment, the digital wallet application may use the wireless capabilities of the electronic device (e.g., near field communication) to receive the banking product identifier.
[0072] In one embodiment, the user may optionally select a communication channel to receive a verification code on, such as text/SMS, email, voice, in-application messaging, etc.
[0073] In step 410, the digital wallet application, or a back end therefore, may request user authentication from a service provider. The digital wallet application may provide the banking product identifier to the service provider and the communication channel identified by the user, if provided.
[0074] In step 415, the service provider computer program may identify a financial institution that is associated with the banking product, such as an issuer, from the banking product identifier. For example, the service provider computer program may identify the financial institution from, for example, a bank identification number, a routing number, or a user identification of the financial institution.
[0075] The service provider computer program may then submit a request for authentication and the banking product identifier to the financial institution. If provided, the service provider computer program may also communicate the communication channel for the verification code that was identified by the user.
[0076] In step 420, a financial institution computer program executed by the financial institution, such as a verification computer program, may generate a verification code, such as a random alphanumeric code. The verification code may have any suitable number of digits and/or characters.
[0077] Alternatively, the service provider computer program may generate and provide the verification code to the financial institution computer program, and the financial institution computer program may use that verification code to authenticate the user.
[0078] In step 425, the financial institution computer program may retrieve user contact information for the banking product identifier from, for example, a user profile in a customer information database. The user contact information may include a SMS address, and email address, an identifier for a financial institution mobile application, etc.
[0079] In step 430, the financial institution computer program may send the verification code to the user electronic device. In one embodiment, if provided, the financial institution computer program may use the communication channel identified by the user. [0080] Alternatively, the financial institution computer program may randomly select the communication channel, may select the communication channel that was most recently updated, may select the communication channel that has successfully been used before, etc.
[0081] In step 435, the user electronic device may receive the verification code, and the user may enter the verification code into the digital wallet application user interface. In one embodiment, the operating system for the user electronic device may pre-populate the user interface with the verification code.
[0082] In another embodiment, the user may enter the verification code to an application associated with the financial institution, such as an issuer application.
[0083] In step 440, the digital wallet application may communicate the entered verification code to the service provider, and the service provider may then provide the entered verification code to the financial institution.
[0084] In one embodiment, if the user enters the verification code into the application that is associated with the financial institution, the application may provide the verification code to the financial institution without involving the service provider.
[0085] In step 445, the financial institution computer program may validate the verification code. If the verification code is valid (e.g., matches the verification code generated by the financial institution computer program), in step 450, the financial institution computer program may authorize the digital wallet application to add the banking product. In one embodiment, this may be done by infoiming the service provider that the authentication was successful, and the service provider may then authorize the digital wallet to add the banking product. In another embodiment, the financial institution computer program may inform the application that is associated with the financial institution, and the application may inform the digital wallet application of the successful authentication by app-to-app communication.
[0086] If the verification code is not valid (e.g., does not match the verification code generated by the financial institution computer program or is not received within a certain period of time), in step 455, the financial institution computer program may instruct the digital wallet application to not add the banking product. This may also be achieved by informing the service provider or the application associated with the financial institution that authentication was unsuccessful.
[0087] Figure 5 depicts an exemplary computing system for implementing aspects of the present disclosure. Figure 5 depicts exemplary computing device 500. Computing device 500 may represent the system components described herein. Computing device 500 may include processor 505 that may be coupled to memory 510. Memory 510 may include volatile memoiy. Processor 505 may execute computer-executable program code stored in memory 510, such as software programs 515. Software programs 515 may include one or more of the logical steps disclosed herein as a programmatic instruction, which may be executed by processor 505. Memory 510 may also include data repository 520, which may be nonvolatile memoiy for data persistence. Processor 505 and memory 510 may be coupled by bus 530. Bus 530 may also be coupled to one or more network interface connectors 540, such as wired network interface 542 or wireless network interface 544. Computing device 500 may also have user interface components, such as a screen for displaying graphical user interfaces and receiving input from the user, a mouse, a keyboard and/or other input/output components (not shown). [0088] Although several embodiments have been disclosed, it should be recognized that these embodiments are not exclusive to each other, and features from one embodiment may be used with others.
[0089] Hereinafter, general aspects of implementation of the systems and methods of embodiments will be described.
[0090] Embodiments of the system or portions of the system may be in the form of a “processing machine,” such as a general-purpose computer, for example. As used herein, the term “processing machine” is to be understood to include at least one processor that uses at least one memory. The at least one memory stores a set of instructions. The instructions may be either permanently or temporarily stored in the memory or memories of the processing machine. The processor executes the instructions that are stored in the memory or memories in order to process data. The set of instructions may include various instructions that perform a particular task or tasks, such as those tasks described above. Such a set of instructions for performing a particular- task may be characterized as a program, software program, or simply software.
[0091] In one embodiment, the processing machine may be a specialized processor.
[0092] In one embodiment, the processing machine may be a cloud-based processing machine, a physical processing machine, or combinations thereof.
[0093] As noted above, the processing machine executes the instructions that are stored in the memory or memories to process data. This processing of data may be in response to commands by a user or users of the processing machine, in response to previous processing, in response to a request by another processing machine and/or any other input, for example. [0094] As noted above, the processing machine used to implement embodiments may be a general-purpose computer. However, the processing machine described above may also utilize any of a wide variety of other technologies including a special purpose computer, a computer system including, for example, a microcomputer, mini-computer or mainframe, a programmed microprocessor, a micro- confroller, a peripheral integrated circuit element, a CSIC (Customer Specific Integrated Circuit) or ASIC (Application Specific Integrated Circuit) or other integrated circuit, a logic circuit, a digital signal processor, a programmable logic device such as a FPGA (Field- Programmable Gate Array), PLD (Programmable Logic Device), PLA (Programmable Logic Array), or PAL (Programmable Array Logic), or any other device or arrangement of devices that is capable of implementing the steps of the processes disclosed herein.
[0095] The processing machine used to implement embodiments may utilize a suitable operating system.
[0096] It is appreciated that in order to practice the method of the embodiments as described above, it is not necessary that the processors and/or the memories of the processing machine be physically located in the same geographical place. That is, each of the processors and the memories used by the processing machine may be located in geographically distinct locations and connected so as to communicate in any suitable manner. Additionally, it is appreciated that each of the processor and/or the memory may be composed of different physical pieces of equipment. Accordingly, it is not necessary that the processor be one single piece of equipment in one location and that the memory be another single piece of equipment in another location. That is, it is contemplated that the processor may be two pieces of equipment in two different physical locations. The two distinct pieces of equipment may be connected in any suitable manner. Additionally, the memory may include two or more portions of memory in two or more physical locations.
[0097] To explain further, processing, as described above, is performed by various components and various memories. However, it is appreciated that the processing performed by two distinct components as described above, in accordance with a further embodiment, may be performed by a single component. Further, the processing perfonned by one distinct component as described above may be performed by two distinct components.
[0098] In a similar manner, the memory storage performed by two distinct memory portions as described above, in accordance with a further embodiment, may be perfonned by a single memory portion. Further, the memory storage performed by one distinct memoiy portion as described above may be performed by two memory portions.
[0099] Further, various technologies may be used to provide communication between the various processors and/or memories, as well as to allow the processors and/or the memories to communicate with any other entity; i.e., so as to obtain further instructions or to access and use remote memory stores, for example. Such technologies used to provide such communication might include a network, the Internet, Intranet, Extranet, a LAN, an Ethernet, wireless communication via cell tower or satellite, or any client server system that provides communication, for example. Such communications technologies may use any suitable protocol such as TCP/IP, UDP, or OSI, for example.
[0100] As described above, a set of instructions may be used in the processing of embodiments. The set of instructions may be in the fonn of a program or software. The software may be in the form of system software or application software, for example. The software might also be in the form of a collection of separate programs, a program module within a larger program, or a portion of a program module, for example. The software used might also include modular programming in the form of object-oriented programming. The software tells the processing machine what to do with the data being processed.
[0101] Further, it is appreciated that the instructions or set of instructions used in the implementation and operation of embodiments may be in a suitable form such that the processing machine may read the instructions. For example, the instructions that form a program may be in the form of a suitable programming language, which is converted to machine language or object code to allow the processor or processors to read the instructions. That is, written lines of programming code or source code, in a particular programming language, are converted to machine language using a compiler, assembler or interpreter. The machine language is binary coded machine instructions that are specific to a particular type of processing machine, i.e., to a particular type of computer, for example. The computer understands the machine language.
[0102] Any suitable programming language may be used in accordance with the various embodiments. Also, the instructions and/or data used in the practice of embodiments may utilize any compression or encryption technique or algorithm, as may be desired. An encryption module might be used to encrypt data. Further, files or other data may be decrypted using a suitable decryption module, for example.
[0103] As described above, the embodiments may illustratively be embodied in the form of a processing machine, including a computer or computer system, for example, that includes at least one memory. It is to be appreciated that the set of instructions, i.e., the software for example, that enables the computer operating system to perform the operations described above may be contained on any of a wide variety of media or medium, as desired. Further, the data that is processed by the set of instructions might also be contained on any of a wide variety of media or medium. That is, the particular medium, i.e., the memory in the processing machine, utilized to hold the set of instructions and/or the data used in embodiments may take on any of a variety of physical forms or transmissions, for example. Illustratively, the medium may be in the fonn of a compact disc, a DVD, an integrated circuit, a hard disk, a floppy disk, an optical disc, a magnetic tape, a RAM, a ROM, a PROM, an EPROM, a wire, a cable, a fiber, a communications channel, a satellite transmission, a memory card, a SIM card, or other remote transmission, as well as any other medium or source of data that may be read by the processors.
[0104] Further, the memory or memories used in the processing machine that implements embodiments may be in any of a wide variety of forms to allow the memory to hold instructions, data, or other infoimation, as is desired. Thus, the memory might be in the form of a database to hold data. The database might use any desired arrangement of files such as a flat file arrangement or a relational database arrangement, for example.
[0105] In the systems and methods, a variety of “user interfaces” may be utilized to allow a user to interface with the processing machine or machines that are used to implement embodiments. As used herein, a user interface includes any hardware, software, or combination of hardware and software used by the processing machine that allows a user to interact with the processing machine. A user interface may be in the form of a dialogue screen for example. A user interface may also include any of a mouse, touch screen, keyboard, keypad, voice reader, voice recognizer, dialogue screen, menu box, list, checkbox, toggle switch, a pushbutton or any other device that allows a user to receive infonnation regarding the operation of the processing machine as it processes a set of instructions and/or provides the processing machine with information. Accordingly, the user interface is any device that provides communication between a user and a processing machine. The information provided by the user to the processing machine through the user interface may be in the form of a command, a selection of data, or some other input, for example.
[0106] As discussed above, a user interface is utilized by the processing machine that perfonns a set of instructions such that the processing machine processes data for a user. The user interface is typically used by the processing machine for interacting with a user either to convey information or receive information from the user. However, it should be appreciated that in accordance with some embodiments of the system and method, it is not necessary that a human user actually interact with a user interface used by the processing machine. Rather, it is also contemplated that the user interface might interact, i.e., convey and receive information, with another processing machine, rather than a human user. Accordingly, the other processing machine might be characterized as a user. Further, it is contemplated that a user interface utilized in the system and method may interact partially with another processing machine or processing machines, while also interacting partially with a human user.
[0107] It will be readily understood by those persons skilled in the art that embodiments are susceptible to broad utility and application. Many embodiments and adaptations of the present invention other than those herein described, as well as many variations, modifications and equivalent arrangements, will be apparent from or reasonably suggested by the foregoing description thereof, without departing from the substance or scope.
[0108] Accordingly, while the embodiments of the present invention have been described here in detail in relation to its exemplary embodiments, it is to be understood that this disclosure is only illustrative and exemplary of the present invention and is made to provide an enabling disclosure of the invention. Accordingly, the foregoing disclosure is not intended to be construed or to limit the present invention or otherwise to exclude any other such embodiments, adaptations, variations, modifications or equivalent arrangements.

Claims

CLAIMS What is claimed is:
1. A method for enhancing digital wallet security, comprising: receiving, at a service provider computer program executed by a service provider electronic device, a request from a computer program executed by a user electronic device for user authentication with a product identifier for a product; generating, by the service provider computer program, a verification code; communicating, by the service provider computer program, the product identifier and the verification code to a verification computer program executed by a backend associated with a provider of the product identifier, wherein the verification computer program is configured to retrieve user contact information for a user associated with the product identifier and communicate the verification code to the user electronic device; receiving, by the service provider computer program, a received verification code from the computer program, wherein the received verification code was received at the user electronic device; and communicating, by the service provider computer program, authorization for an action involving the product to the computer program in response to the received verification code matching the verification code.
2. The method of claim 1, further comprising: communicating, by the service provider computer program, denial for the action involving the product to the computer program in response to the received verification code not matching the verification code.
3. The method of claim 1, wherein the product comprises a banking product, and the action comprises adding the banking product to a digital wallet application executed by the user electronic device.
4. The method of claim 1, further comprising: receiving, by the service provider computer program, an identification of a communication channel to send the verification code to the user electronic device; and communicating, by the service provider computer program, the identification of the communication channel to the verification computer program, wherein the verification computer program is configured communicate the verification code to the user electronic device over the communication channel.
5. The method of claim 1, wherein the verification code is communicated to the user electronic device by short messaging service, electronic mail, voice communication, or in-app messaging.
6. A method for enhancing digital wallet security, comprising: receiving, by a verification computer program executed by a backend associated with a provider of a product and from a service provider computer program, a request to authenticate a user comprising a product identifier for the product; retrieving, by the verification computer program, user contact information associated with the product identifier; communicating, by the verification computer program, a request for authenticating information to the user contact information; receiving, by the verification computer program, received authenticating information; retrieving, by the verification computer program, stored authenticating information for the user associated with the product identifier; and communicating, by the verification computer program and to the service provider computer program, authorization for an action involving the product in response to the received authenticating information matching the stored authenticating information.
7. The method of claim 6, further comprising: communicating, by the verification computer program and to the service provider computer program, denial for the action involving the product to the computer program in response to the received authenticating information not matching the stored authenticating information.
8. The method of claim 6, wherein the product comprises a banking product, and the action comprises adding the banking product to a digital wallet application executed by a user electronic device.
9. The method of claim 8, wherein the authenticating information comprises a personal identification number or a card verification value for the banking product.
10. The method of claim 6, wherein the authenticating information comprises a driver’s license number for the user.
11. The method of claim 6, wherein the authenticating information comprises out of wallet information for the user.
12. The method of claim 6, further comprising: receiving, by the verification computer program and from the service provider computer program, an identification of a communication channel to send the request for authenticating infoimation; and communicating, by the verification computer program, the request for authenticating information over the communication channel.
13. The method of claim 6, wherein the request for authenticating information is communicated by short messaging service, electronic mail, or in- app messaging.
14. A system, comprising: a user electronic device executing a user computer program; a service provider electronic device executing a service provider computer program; and a backend executing a verification computer program; wherein: the user computer program submits a request to add a product associated with a product identifier to the user computer program to the service provider computer program; the service provider computer program submits a request to authenticate a user associated with the product identifier to the verification computer program; the verification computer program retrieves user contact information associated with the product identifier; the verification computer program communicates a request for authenticating infonnation to the user electronic device using the user contact information; the verification computer program receives received authenticating information from the user electronic device; the verification computer program retrieves stored authenticating information for the user associated with the product identifier; and the verification computer program communicates authorization for an action involving the product to the service provider in response to the received authenticating information matching the stored authenticating infonnation.
15. The system of claim 14, wherein the verification computer program communicates no authorization for the action involving the product to the computer program to the service provider in response to the received authenticating infonnation matching the stored authenticating information.
16. The system of claim 14, wherein the product comprises a banking product, the user computer program comprises a digital wallet application, and the action comprises adding the banking product to the digital wallet application.
17. The system of claim 16, wherein the authenticating information comprises a personal identification number or a card verification value for the banking product.
18. The system of claim 14, wherein the authenticating information comprises a driver’s license number for the user.
19. The system of claim 14, wherein the authenticating information comprises out of wallet information for the user.
20. The system of claim 14, wherein the user electronic device further executes a computer program associated with the backend, and the verification computer program communicates the request for authenticating information to the computer program associated with the backend, and the computer program associated with the backend communicates the received authenticating information to the verification computer program.
EP23822198.0A 2022-11-17 2023-11-09 Systems and methods for enhancing digital wallet security Pending EP4619922A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US18/056,645 US20240169345A1 (en) 2022-11-17 2022-11-17 Systems and methods for enhancing digital wallet security
PCT/US2023/079279 WO2024107590A1 (en) 2022-11-17 2023-11-09 Systems and methods for enhancing digital wallet security

Publications (1)

Publication Number Publication Date
EP4619922A1 true EP4619922A1 (en) 2025-09-24

Family

ID=89190501

Family Applications (1)

Application Number Title Priority Date Filing Date
EP23822198.0A Pending EP4619922A1 (en) 2022-11-17 2023-11-09 Systems and methods for enhancing digital wallet security

Country Status (3)

Country Link
US (1) US20240169345A1 (en)
EP (1) EP4619922A1 (en)
WO (1) WO2024107590A1 (en)

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10140615B2 (en) * 2014-09-22 2018-11-27 Visa International Service Association Secure mobile device credential provisioning using risk decision non-overrides
US11615395B2 (en) * 2019-12-23 2023-03-28 Capital One Services, Llc Authentication for third party digital wallet provisioning

Also Published As

Publication number Publication date
US20240169345A1 (en) 2024-05-23
WO2024107590A1 (en) 2024-05-23

Similar Documents

Publication Publication Date Title
US11587068B2 (en) Systems and methods for supporting legacy and tokenized e-commerce
US12254473B2 (en) Systems, methods, and devices for integrating a first party service into a second party computer application
US11928669B2 (en) Systems and methods for mobile wallet payments
WO2019236718A1 (en) Systems and methods for using a cryptogram lockbox
US20250259163A1 (en) Systems and methods for payment token provisioning with variable risk evaluation
US10776785B2 (en) Systems and methods for device authentication
US12406252B2 (en) Systems and methods for integrated digital wallet payments
US20230033497A1 (en) Token processing with selective de-tokenization for proximity based access device interactions
WO2024151702A1 (en) Systems and methods for dynamic risk-assessed serialization of user challenges
US12026686B2 (en) Systems and methods for facilitating payment service-based checkout with a merchant
US20240169345A1 (en) Systems and methods for enhancing digital wallet security
WO2025096256A1 (en) Systems and methods for identity verification using identity tokens
US11507954B2 (en) Systems and methods for conducting transactions using a surrogate pin
US11283618B1 (en) Transaction unique loyalty identification programs (TULIP)
US20250356351A1 (en) Systems and methods for transaction verification by tap
US20260046342A1 (en) Systems and methods for pull notifications and interacting on both web and mobile channels
US20230306393A1 (en) Systems and methods for integrating pay by bank services
US20250363477A1 (en) Systems and methods for mobile device payment using tap
US20260024092A1 (en) Systems and method for conducting payment network-less transactions
US20230281597A1 (en) Systems and methods for proximity-based mobile device person-to-person payments
US20250139622A1 (en) Systems and methods for throttled sharing of personal information
US20250139627A1 (en) Systems and methods for offline processing of biometrically-enabled payment transactions
US12099986B2 (en) Systems and methods for providing embedded banking services
US12282937B2 (en) Systems and methods for payment product verification and authorization using a customer identifier
US20250385794A1 (en) Systems and methods for securing login authentication

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: UNKNOWN

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20250429

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR

DAV Request for validation of the european patent (deleted)
DAX Request for extension of the european patent (deleted)